Live data from Hacker News

Show HN: Beeper Mini – iMessage client for Android

beeper.com

231–240 of 902 posts

Re: Show HN: Beeper Mini – iMessage client for Android

#231
post #99

Earlier quoted context omitted.

If Apple bans this they will have to answer to EU courts. I very much doubt they will in this political climate.

And if Beeper keeps it up they’re likely running afoul of the CFAA in the US. The EU doesn’t rule the world. They haven’t forced iMessage open yet, and Apple is clearly trying to avoid it with their announced RCS support. I don’t think things are as far along as you do.

Probably because no one uses iMessage in the EU.

Re: Show HN: Beeper Mini – iMessage client for Android

#232
post #164

Earlier quoted context omitted.

Apple announced that they will support RCS. Presumably they will not charge Android users for sending RCS messages to iPhone users right?

RCS isn't encrypted, doesn't work without phones, doesn't have a single identity across multiple devices, etc so it's not going to replace iMessage.

RCS can be encrypted. Whether Apple chooses to do so is yet to be seen of course, but I'm guessing they will reserve encryption for "blue bubbles."

Re: Show HN: Beeper Mini – iMessage client for Android

#233

At this point, why not just wait for Apple to release their RCS implementation? The nicest thing about iMessage (for me, at least) has always been that it was a significant improvement to SMS that just worked, with graceful fallback to SMS for anyone who didn't use it. No installing third party apps, wondering if someone new I wanted to contact would be on that messaging app, etc. A nice bonus, but not something that…

> with graceful fallback Have you ever tried to stop having an Apple device? Hopefully better now, but a few years ago there was no way to unlink iMessage. So say good bye to all your Apple friends, as them texting you goes to the Apple cloud and not your new phone.

Yep, I used to switch back and forth between iPhone and Android every couple years. I'd deregister the phone number when switching over to Android. I don't remember a time they didn't offer that ability.

Re: Show HN: Beeper Mini – iMessage client for Android

#234

It seems that at least the push notification registration part uses a "leaked/extracted" FairPlay private key [1]. As far as I understand, FairPlay certificates/keys should be unique to each iDevice. Couldn't Apple trivially ban all subscriptions originating from this fake device? The comment says you know how to generate more; does Beeper Mini generate one for each install? Why would Apple believe those certificates…

Does this look like the same file from the deleted repo? https://github.com/rdxunlock/albertsimlockapple/blob/main/AL...

I'd love to see an open source version of Beeper with no analytics. I'd be happy to host my own notification server.

Re: Show HN: Beeper Mini – iMessage client for Android

#235

From their blogpost: https://blog.beeper.com/p/beeper-cloud-and-product-roadmap > Everything changed in August when a security researcher reverse engineered the iMessage protocol. > At a high level, here’s our product plan for the near future (in very rough order, and very subject to change): > Add support for SMS, WhatsApp and Signal into Beeper Mini, using the same end-to-end encrypted client-side connection archit…

> Signal is the same, they C&D every fork that becomes popular, the only official clients are the CLI and the ones they release This always rubbed me the wrong way and made it seem like it's an NSA operation

Nah. Not NSA. CIA

Re: Show HN: Beeper Mini – iMessage client for Android

#236

Its awesome to reverse engineer this... but.. At the end of the day, this product is taking money for using Apple Services with no recompense to Apple. It won't last. Apple should have added an iMessage client to Android (and charged for it) long, long, long ago, but it doesn't change the ethics problem here. (This is the downside to the "just pay for it with hardware" model people always love rather than paying subs…

Agree. We have seen this before.

What if someone reverse engineered Twitter's services and built a separate client and tried to monetize it. What would Twitter do?

What if someone reverse engineered Reddit's services and built a separate client and tried to monetize it. What would Reddit do?

What if someone reverse engineered Instagram's services and built a separate client and tried to monetize it. What would Instagram do?

Re: Show HN: Beeper Mini – iMessage client for Android

#237

Recently I got a spam iMessage from a sort of empty contact. There was no number, no email address. I thought this was impossible, that there had to some kind of ID connected. Can someone explain what's going on?

I just got some iMessage spam yesterday. Now I know why.

This jailbreak will make it less likely for someone to be able to trust iMessage.

Re: Show HN: Beeper Mini – iMessage client for Android

#238

Earlier quoted context omitted.

Last time I checked, everyone knows SMS is cleartext and can't take over your phone in the profound way built-in 1st party apps/services you emphatically cannot remove (only toggle) can seize the means of production so to speak.

“Everyone” may be overly broad… just about everybody with any technical inclination knows yes, but for many years now the overwhelming majority of smartphone users have not been particularly technically inclined, and as such I would not expect most of them to be aware of the security and privacy implications that come with use of the various messaging services. With that in mind, I’d say that most messaging apps don’…

Didn't mean to sound so bratty, I just get frustrated by this topic. My apologies if I was a bit testy. I just mean that iMessage is extremely misleading and overly-technical in what it takes to truly have a chance at making it secure and private to the extent it extolls itself.

This shit matters now that people aren't able to receive proper reproductive care and education and other grey areas where Apple is setting its users and itself up for terrible and unjust outcomes that depend on everyone but Apple having flawed/imperfect information and Apple pretending 'Saul Goodman...

Re: Show HN: Beeper Mini – iMessage client for Android

#239
post #38

OK, took a while to figure out what it is, as I barely know anyone using iphone. Though it's not for me, BUT if they deliver this: > Over time, we will be adding all networks that Beeper supports into Beeper Mini, including SMS/RCS, WhatsApp, Messenger, Signal, Telegram, Instagram, Twitter, Slack, Discord, Google Chat and Linkedin. We'll also bring Beeper Mini to desktop and iOS. I'm interested, even if it's paid. I'…

Happy Beeper customer and original poster here to tell you: Beeper Cloud is already out there and works really well! It's also free, though you'll have to get through the waitlist somehow. It doesn't perfectly replace every app just yet but it covers the most important functionality extremely well. And it's available on mobile as well as desktop devices.

IIRC, though, Beeper Cloud does not come with end-to-end encryption on messaging services that usually have that feature through their regular app. Messages are encrypted between your device and Beeper's servers, and between Beeper's servers and the other end of the conversation, but the Beeper folks can still read your messages if they want.

(Please correct me if I'm wrong; the architecture of their product is pretty confusing.)

Re: Show HN: Beeper Mini – iMessage client for Android

#240

It seems that at least the push notification registration part uses a "leaked/extracted" FairPlay private key [1]. As far as I understand, FairPlay certificates/keys should be unique to each iDevice. Couldn't Apple trivially ban all subscriptions originating from this fake device? The comment says you know how to generate more; does Beeper Mini generate one for each install? Why would Apple believe those certificates…

Snazzy Labs did an overview video [1] about this implementation. According to them, reusing a specific hardware token is such s common practice that Apple would need to "redesign their entire authentication and delivery strategy" to mitigate this problem. I guess we'll see how this statement holds up in the coming weeks/months. [1] https://youtu.be/S24TDRxEna4?t=5m38s

We're talking about a company that changes CPU architectures for their ecosystem every few years, completely seamlessly. If redesigning their entire authentication and delivery strategy is what it will take to mitigate this problem, Apple will do it.
Post reply on HN